Azure / Azure/Azure-Landing-Zones

Audit with Sandbox

Open
#255 2 comments 0 reactions 0 assignees View on GitHub
Transfer From: Enterprise-Scale :arrow_right:
Dominant language
PowerShell
Stars
96
Forks
70
Avg merge
3d 1h
Merged PRs (30d)
7

Description

At times people would like to develop things for a subscription, which resided e.g. underneath corp.
However, the policies keep them for getting their things done.

To circumvent that you could have

- all policy assignment with effect deny on the landing zones management group should have a matching policy assignemnet with
- all management groups underneath landing zone, would have a matching management group underneath sandbox
- as before, the policy assignment with effect deny underneath landing zone would have the effect audit underneath the management group sandbox.

This way landing zone and sandbox would be well separated. And you would be able to verify which policies you are violating for your final landing zone .

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the repository’s Azure landing-zone documentation for management groups and policy assignments. Clarify the intended landing-zone and sandbox hierarchy, the matching deny and audit assignments, and the acceptance criteria before proposing a design.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
cloud
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.